---------- Forwarded message ---------
From: Asterisk Development Team <asteriskt...@digium.com>
Date: ter, 19 de set de 2017 às 14:35
Subject: [asterisk-dev] Asterisk 11.25.3, 13.17.2, 14.6.2, Asterisk
11.6-cert18, Asterisk 13.13-cert6 Now Available (Security Release)
To: Asterisk Developers Mailing List <asterisk-...@lists.digium.com>


The Asterisk Development Team has announced security releases for Asterisk
11, 13, and 14, and for Certified Asterisk 11.6 and 13.13. The available
security release versions are 11.25.3, 13.17.2, 14.6.2, 11.6-cert18, and
13.13-cert6.

These releases are available for immediate download at

http://downloads.asterisk.org/pub/telephony/asterisk/releases
http://downloads.asterisk.org/pub/telephony/certified-asterisk/releases/

The release of these versions resolves the following security
vulnerabilities:

* AST-2017-008: Insufficient RTCP packet validation could allow reading
stale buffer contents and when combined with the “nat” and “symmetric_rtp”
options allow redirecting where Asterisk sends the next RTCP report.

The RTP stream qualification to learn the source address of media always
accepted the first RTP packet as the new source and allowed what
AST-2017-005 was mitigating.  The intent was to qualify a series of packets
before accepting the new source address.

For a full list of changes in the current releases, please see the
ChangeLogs:

http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-11.25.3
http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-13.17.2
http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-14.6.2

http://downloads.asterisk.org/pub/telephony/certified-asterisk/releases/ChangeLog-certified-11.6-cert18
http://downloads.asterisk.org/pub/telephony/certified-asterisk/releases/ChangeLog-certified-13.13-cert6

The security advisories are available at:

 * http://downloads.asterisk.org/pub/security/AST-2017-008.pdf

Thank you for your continued support of Asterisk!
--
_____________________________________________________________________
-- Bandwidth and Colocation Provided by http://www.api-digital.com --

asterisk-dev mailing list
To UNSUBSCRIBE or update options visit:
   http://lists.digium.com/mailman/listinfo/asterisk-dev
_______________________________________________
KHOMP: completa linha de placas externas FXO, FXS, GSM e E1
Media Gateways de 1 a 64 E1s para SIP com R2, ISDN e SS7
Intercomunicador e acesso remoto via rede IP e telefones IP
Conheça todo o portfólio em www.Khomp.com
_______________________________________________
Para remover seu email desta lista, basta enviar um email em branco para 
asteriskbrasil-unsubscr...@listas.asteriskbrasil.org

Responder a